AI Business

OpenAI Maps Safety Framework to EU AI Act Requirements as Enforcement Looms

OpenAI has detailed how its existing safety and transparency practices align with the EU's General-Purpose AI Code of Practice ahead of regulatory enforcement. The company points to pre-release testing, published system cards, and red-teaming efforts as evidence of compliance.

·4 min read
OpenAI aligns safety practices with EU AI Act’s GPAI Code
OpenAI aligns safety practices with EU AI Act’s GPAI Code

As the EU AI Act moves toward enforcement, OpenAI has laid out its alignment with the regulatory framework's expectations for safety, security, and openness. The organization has both contributed to and formally backed the EU's General-Purpose AI (GPAI) Code of Practice alongside the Code of Practice on Transparency of AI-Generated Content, each developed through collaborative multi-stakeholder efforts.

The GPAI Code establishes consistent standards for transparency, safety, and security among general-purpose models offered or used across the EU. OpenAI references several current practices as proof of near-compliance with this standard: model testing before release, accompanying system cards published with significant product announcements, and external red-teaming conducted via its Red Teaming Network. Additionally, the company maintains a publicly available Model Spec document that outlines its approach to directing model behavior.

Two foundational internal documents underpin this work. The Preparedness Framework, introduced in 2023 and revised in 2025, establishes OpenAI's methodology for identifying, assessing, and controlling significant hazards from cutting-edge systems. A complementary Frontier Governance Framework extends this foundation by demonstrating how the company's safety and security operations correspond to regulatory obligations, particularly the GPAI Code.

According to OpenAI, these paired frameworks collectively address risk evaluation, protective measures, model disclosure, security infrastructure, crisis management, and the involvement of independent specialists in the oversight process.

OpenAI highlights its involvement in the Frontier Model Forum, partnerships with the US Center for AI Standards and Innovation and the UK AI Security Institute, and support for independent evaluation frameworks. The company frames this participation as advancing industry-wide safety research and establishing consistent evaluation criteria rather than restricting knowledge to its own operations.

Provenance gets harder as modalities multiply

A distinct challenge addressed by the Transparency Code involves enabling recognition of content that has been generated or modified through AI systems.

OpenAI's strategy employs two complementary tools designed to work in concert. Content Credentials, based on the C2PA standard, embed contextual information directly into files. SynthID watermarking functions as a secondary indicator for instances where embedded data becomes lost during distribution or platform transfers.

The company is broadening its reach from visual media into voice generation, and indicates plans to broaden provenance tracking to encompass additional formats, including written text, as relevant standards and infrastructure develop further. OpenAI is simultaneously creating resources and documentation for developers who must satisfy their own transparency requirements when utilizing its models as a foundation.

This approach does not completely resolve the provenance challenge. Embedded information frequently disappears, and identifiers may not persist when transferred between different systems. No individual mechanism—whether based on encryption or watermarking—addresses all scenarios independently. OpenAI's strategy involves stacking multiple safeguards alongside continued participation in industry-wide standards development rather than asserting that any single solution fully addresses the issue.

Cybersecurity as the test case for adaptive governance

Technologies enabling security specialists to locate and resolve weaknesses can equally enable malicious actors to discover them. OpenAI contends that its Trusted Access for Cyber programme addresses this tension by permitting authorized security professionals to leverage more sophisticated cyber capabilities while constraining misuse potential.

The programme has now expanded to include a European component. OpenAI reports launching its EU Cyber Action Plan in May 2026, collaborating with EU institutions, national cybersecurity authorities, commercial partners, and critical infrastructure operators to furnish them with access to its more sophisticated cyber models.

The stated objective involves bolstering cybersecurity resilience throughout Europe. OpenAI makes claims about whether "most advanced" capabilities translate into concrete defensive improvements within participating agencies, though the available information contains no third-party confirmation of actual programme results.

OpenAI characterizes this initiative as consistent with the European Commission's Action Plan on Cybersecurity and Artificial Intelligence, which emphasizes coordinated management of AI-related dangers alongside leveraging AI for defensive strengthening, encompassing restricted access protocols for cyber defense applications.

OpenAI indicates it will modify its compliance strategy as the EU AI Act rolls out, and anticipates continuous feedback from authorities and participants in the regulatory development process. The organization argues that regulations require sufficient adaptability to evolve alongside technological advancement, permitting enterprises and institutions to realize ongoing advantages.

The GPAI Code and Transparency Code remain relatively recent instruments, and OpenAI's compliance documentation continues to evolve rather than represent a final state. Organizations constructing applications on OpenAI's models within regulated European jurisdictions should regard the current system cards and Frontier Governance Framework as preliminary reference materials for their own compliance work, not as a complete substitute for independent assessment.